Daily Writeups
3.53K subscribers
2 photos
130K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
Title: Subscription Bypass Leading to Full Access to Paid Features
════════════════════════
𐀪 Author: Hossam Hamada
════════════════════════
Time: Thu, 25 Dec 2025 01:14:04 GMT
════════════════════════
Tags: #bug_bounty #bug_hunting #writing_tips #business_logic #bugbounty_writeup
Title: Thoughts about email verification process in web applications
════════════════════════
𐀪 Author: Wsxcxx
════════════════════════
Time: Thu, 25 Dec 2025 01:53:21 GMT
════════════════════════
Tags: #sign_up #programming #application_security #application_development #email_verification
Title: TryHackMe: Year of the Owl Writeup
════════════════════════
𐀪 Author: cbev
════════════════════════
Time: Thu, 25 Dec 2025 01:20:38 GMT
════════════════════════
Tags: #pentesting #cybersecurity #information_security #tryhackme
Title: The Patch Hunter: Automating 1-Day Exploits with DiffRays and IDA Pro
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 25 Dec 2025 03:06:01 +0000
════════════════════════
Tags: #Open Source Tool #AutoDiff #Binary Diffing #CVE #DiffRays #Exploit Development #IDA Domain API #IDA Pro #Patch Analysis #reverse engineering #Vulnerability Research #Winbindex
Title: Unlocking the Speed of Light: How Hardware-Accelerated BitLocker Saves Your FPS
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 25 Dec 2025 02:59:14 +0000
════════════════════════
Tags: #Windows #BitLocker #CPU Offloading #Encryption #Intel Panther Lake #Microsoft Ignite 2025 #NVMe #SSD performance #Windows 11 #Windows Security #XTS_AES_256
Title: The Robot Revolter: How Hackers Turned a $14,000 Humanoid Into a Physical Attacker
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 25 Dec 2025 02:57:39 +0000
════════════════════════
Tags: #Vulnerability #AI safety #cybersecurity #DARKNAVY #GEEKCon 2025 #Humanoid Robots #IoT Security #Physical Botnet #Robot Hacking #Unitree G1 #Unitree Go2 #Voice Command Exploit
Title: The Dark Side of Telegram: Inside the $2B/Month Crypto Laundering Bazaars
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 25 Dec 2025 02:56:15 +0000
════════════════════════
Tags: #Cybercriminals #Crypto Fraud #Dark Web #Elliptic #Huione Guarantee #Money Laundering #pig butchering #Southeast Asia #Telegram #Tether #Tudou Guarantee #USDT #Xinbi Guarantee
Title: Emergency Patch: Microsoft Issues Out-of-Band Fix for Broken MSMQ Infrastructure
════════════════════════
𐀪 Author: ddos
════════════════════════
Time: Thu, 25 Dec 2025 02:54:51 +0000
════════════════════════
Tags: #Windows #bug fix #Enterprise IT #IIS #KB5074976 #Microsoft #MSMQ #Out_of_Band #Patch Tuesday #Sysadmin #Windows Server #Windows Update
Title: The AMX Lockdown: Critical KVM Bug Allows Guest VMs to Crash Linux Hosts
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 03:11:17 +0000
════════════════════════
Tags: #Linux #Cloud Security #dos #FPU #Hypervisor #Intel AMX #kernel panic #KVM #Linux Kernel #Paolo Bonzini #red hat #virtualization #Xeon Scalable #XSAVE
Title: Beyond Pixel: Google Rebrands Magic Cue to Bring Proactive AI to All Androids
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 02:30:54 +0000
════════════════════════
Tags: #Android #AI #android #Contextual Suggestions #Gemini Nano #google #Google Play Services #machine_learning #Magic Cue #Pixel 10 #privacy #Private Compute Core
Title: Intel’s 14A/18A Super Chip: The AI “System Foundry” That Challenges TSMC
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 02:19:24 +0000
════════════════════════
Tags: #Technology #14A #18A_PT #AI Silicon #EMIB_T #Foveros Direct 3D #HBM4 #HBM5 #Heterogeneous Integration #Intel Foundry #PowerDirect #RibbonFET 2 #TSMC CoWoS
Title: The End of AirPods’ Monopoly: Apple to Unlock Proximity Pairing and Smartwatch Replies
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 02:01:03 +0000
════════════════════════
Tags: #Technology #AirPods #Apple #Apple Watch #Bluetooth #DMA #European Union #iOS 26.3 #iphone #Proximity Pairing #sony #Tech Policy 2026 #Wear OS
Title: Hackers Revive 2020 FortiGate Flaw to Bypass 2FA
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 01:53:12 +0000
════════════════════════
Tags: #Vulnerability Report #2FA bypass #active directory #CVE_2020_12812 #cyber attack #firewall security #FortiGate #Fortinet #LDAP #network_security #Patch Alert #SSL VPN
Title: “LotusBail” Trap: 56,000 Developers Downloaded a Fake WhatsApp API That Works perfectly—While Stealing Everything
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 00:41:07 +0000
════════════════════════
Tags: #Malware #@whiskeysockets/baileys #backdoor #data exfiltration #JavaScript Security #KOI Security #lotusbail #malware #npm #Open Source Security #supply chain attack #WhatsApp API
Title: Evasive Panda APT Hijacks Dictionary.com and App Updates in Two-Year Spree
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 00:37:13 +0000
════════════════════════
Tags: #Cybercriminals #AiTM #cyber_espionage #Daggerfly #DLL Sideloading #DNS Poisoning #Evasive Panda #Kaspersky Labs #malware #MgBot #Software Update Hijack #SohuVA #StormBamboo
Title: High-Severity Flaws in TeamViewer DEX Allow Attackers to Hijack Nomad Services
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 00:33:09 +0000
════════════════════════
Tags: #Vulnerability Report #1E #Code Execution #Command Injection #CVE_2025_44016 #DEX #Digital Employee Experience #Nomad Branch #Patch Tuesday #privilege escalation #TeamViewer #Windows Security
Title: ChatGPT Atlas Under Guard: OpenAI Fortifies Browser Agent Against “Prompt Injection” Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 00:27:15 +0000
════════════════════════
Tags: #Vulnerability Report #Adversarial Training #Agent Mode #AI security #Browser Agent #ChatGPT Atlas #Cyber Security #LLM Safety #OpenAI #Prompt injection #red_teaming
Title: The “lc” Leak: Critical 9.3 Severity LangChain Flaw Turns Prompt Injections into Secret Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 00:22:06 +0000
════════════════════════
Tags: #Vulnerability Report #AI Agents #CVE_2025_68664 #data exfiltration #Environment Variables #Information Disclosure #LangChain #LLM Security #Prompt injection #Python Security #Serialization Injection
Title: Hackers Weaponize npm to Hunt Critical Infrastructure Sales Teams
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 00:19:34 +0000
════════════════════════
Tags: #Cybercriminals #adril7123 #AiTM #Critical Infrastructure #evilginx #Interpack #K_Fair #Manufacturing Security #MicroSecure #Microsoft 365 #npm #phishing #Socket #supply chain attack
Title: Zimbra Under Siege: High-Severity LFI Vulnerability Exposes Internal Files to Unauthenticated Attackers
════════════════════════
𐀪 Author: Ddos
════════════════════════
Time: Thu, 25 Dec 2025 00:11:18 +0000
════════════════════════
Tags: #Vulnerability Report #CVE_2025_67809 #CVE_2025_68645 #Email Security #hardcoded credentials #infosec #lfi #local file inclusion #Patch Update #ZCS #Zimbra